7 min read
React2Shell (CVE-2025-55182): The Critical Vulnerability That Earned a Perfect 10.0 Severity Score
On December 3, 2025, the React team disclosed one of the most critical vulnerabilities in the framework's history: CVE-2025-55182, better known as React2Shell. With a maximum CVSS score of 10.0 and active exploitation within hours of disclosure, this vulnerability represents a serious threat to React Server Components applications. Here's what you need to know and why you should patch immediately.
